Software & SaaS
When a software company says it is "SOC 2 certified," it is pointing to a specific, defined thing — and knowing what that thing is (and isn't) helps you judge the claim. SOC 2 is a framework developed by the American Institute of Certified Public Accountants (AICPA) as part of its System and Organization Controls (SOC) suite. A SOC 2 report is an independent attestation, produced by a licensed CPA firm, on the controls a service organization has in place relevant to one or more of the five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
One distinction matters most: Type I versus Type II. A SOC 2 Type I report evaluates whether controls are suitably designed at a single point in time. A SOC 2 Type II report goes further, testing whether those controls actually operated effectively over a period of time (often 6–12 months). When a vendor advertises "SOC 2 Type II," it is claiming an auditor tested its controls over time, which is a stronger signal than Type I.
SOC 2 is not the only credential you may see. ISO/IEC 27001 is an international standard for information security management systems, and FedRAMP is a U.S. government program authorizing cloud services for federal use, with impact levels (Low, Moderate, High). A password manager that lists FedRAMP High, for example, has met a demanding federal bar — though that authorization applies to specific government offerings, so read what exactly is covered.
A few honest caveats. A SOC 2 report is only as current as its audit period, and the detailed report is usually shared under NDA, so a public "SOC 2 badge" is a summary, not proof you can independently inspect. Certifications also describe process and controls, not a guarantee that no breach can ever happen. Open-source code and published independent penetration-test or cryptography audits (which some vendors post publicly) add a different, complementary kind of transparency. The practical takeaway: treat SOC 2 Type II, ISO 27001, and FedRAMP as meaningful, verifiable signals of a mature security program — and check the vendor's own trust or security page for what is covered and how recently it was assessed. This article is educational and cites the frameworks' official descriptions; it is not a security audit.